Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1353 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)11%💥 PoCNode-postgres PG7/6/201817/6/2026
A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an…
ModificadaAlta (7.5)1.1%—Nodesass Project Nodesass7/6/201817/6/2026
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.1%—Noderequest Project Noderequest7/6/201817/6/2026
noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.2%—Nodemailer.js Project Nodemailer.js7/6/201817/6/2026
nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.1%—Nodemailer-js Project Nodemailer-js7/6/201817/6/2026
nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.2%—Nodecaffe Project Nodecaffe7/6/201817/6/2026
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.2%—Nodeffmpeg Project Nodeffmpeg7/6/201817/6/2026
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.1%—Node-opencv Project Node-opencv7/6/201817/6/2026
node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.2%—Node-openssl Project Node-openssl7/6/201817/6/2026
node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.1%—Node-opensl Project Node-opensl7/6/201817/6/2026
node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.1%—Mssql-node Project Mssql-node7/6/201817/6/2026
mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.1%—Nodemssql Project Nodemssql7/6/201817/6/2026
nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.2%—Nodefabric Project Nodefabric4/6/201817/6/2026
`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.2%—Node-fabric Project Node-fabric4/6/201817/6/2026
`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.2%—Nodesqlite Project Nodesqlite4/6/201817/6/2026
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.2%—Node-sqlite Project Node-sqlite4/6/201817/6/2026
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaMedia (6.5)2.6%—Sync-exec Project Sync-execNodejs Node.js4/6/201817/6/2026
The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the…
ModificadaMedia (5.9)0.93%—Cisco Node-jose4/6/201817/6/2026
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers. node-jose earlier than version 0.9.3 is vulnerable to an invalid curve attack. This allows an attacker to recover the private secret key when JWE with Key Agreement with…
ModificadaAlta (8.1)2.2%—Node-wixtoolset Project Node-wixtoolset4/6/201817/6/2026
wixtoolset is a Node module wrapper around the wixtoolset binaries wixtoolset downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the…
ModificadaAlta (8.1)1.8%—Node-air-sdk Project Node-air-sdk4/6/201817/6/2026
node-air-sdk is an AIR SDK for nodejs. node-air-sdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in…
ModificadaAlta (8.1)0.58%—Node-bsdiff-android Project Node-bsdiff-android4/6/201817/6/2026
node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
ModificadaAlta (8.1)1.8%—Geohey Node-thulac4/6/201817/6/2026
node-thulac is a node binding for thulac. node-thulac downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in…
ModificadaAlta (8.1)2.0%—Nodeschnaps Project Nodeschnaps1/6/201817/6/2026
nodeschnaps is a NodeJS compatibility layer for Java (Rhino). nodeschnaps downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network…
ModificadaAlta (8.1)1.7%—Atom-node-module-installer Project Atom-node-module-installer1/6/201817/6/2026
atom-node-module-installer installs node modules for atom-shell applications. atom-node-module-installer binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the…
ModificadaAlta (8.1)0.58%—Node-browser Project Node-browser1/6/201817/6/2026
node-browser is a wrapper webdriver by nodejs. node-browser downloads resources over HTTP, which leaves it vulnerable to MITM attacks.